Description
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
Published: 2026-06-01
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in the PCTCore64.sys Windows kernel driver of Symantec PC Tools Internet Security allows a user‑mode process to access privileged IOCTL handlers through the driver’s WDM device interface. Because the driver does not enforce proper permissions, a local attacker can invoke privileged commands that bypass normal Windows kernel security checks, enabling the attacker to execute arbitrary operations with kernel‑level privileges. This flaw directly facilitates the acquisition of full system control.

Affected Systems

Symantec PC Tools Internet Security contains the vulnerable PCTCore64.sys driver. No vendor‑specified version numbers were provided, so any installation of the PC Tools Internet Security suite that includes this driver may be affected. Users should verify whether the driver is present by checking the installation directory for PCTCore64.sys.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. Because the exploit requires local access to load or interact with the driver, no known exploitation is reported and the vulnerability is not listed in CISA KEV. An attacker needs to have some user privileges to gain the ability to load the driver or call its IOCTL interface, after which the vulnerability can be abused to perform privileged actions. Although the attack surface is limited to systems running the compromised driver, the impact of successful exploitation is complete control of the machine.

Generated by OpenCVE AI on June 1, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Symantec update that addresses the PCTCore64.sys access control flaw.
  • Enable Windows driver signing enforcement so that only fully signed, approved drivers can be loaded.
  • Restrict local user accounts that have permission to load drivers, enforcing least‑privilege through ACLs or group policy settings.

Generated by OpenCVE AI on June 1, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Symantec
Symantec pc Tools Internet Security
Vendors & Products Symantec
Symantec pc Tools Internet Security

Mon, 01 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 01 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
References

Mon, 01 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-782
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 01 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
Title CVE-2026-8501
References

Subscriptions

Symantec Pc Tools Internet Security
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-06-01T18:55:01.689Z

Reserved: 2026-05-13T20:56:16.307Z

Link: CVE-2026-8501

cve-icon Vulnrichment

Updated: 2026-06-01T18:55:01.689Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-01T17:17:35.513

Modified: 2026-06-01T21:16:47.610

Link: CVE-2026-8501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:54:14Z

Weaknesses
  • CWE-782

    Exposed IOCTL with Insufficient Access Control